Novell
novell
657 CVEs • 111 products
Products (111)
Click to collapseToggle
Products (111)
Click to collapse
CVEs (657)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
12Amazon AristaCanonical+9 more45Amazon Linux Basesystem ModuleCaas Platform+42 moreJul 15, 2026 Apr 22, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is...Show more |
8Almalinux ArchlinuxGentoo+5 more8Almalinux Arch LinuxEnterprise Linux+5 moreJun 29, 2026 Jan 15, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16...Show more |
8Almalinux ArchlinuxGentoo+5 more20Almalinux Arch LinuxDiscovery+17 moreJun 30, 2026 Jan 14, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a p...Show more |
3Nextcloud NovellOpensuse3Backports Sle Nextcloud ServerSuse Linux Enterprise ServerJun 17, 2026 Feb 4, 2020 N/A· v4 5.0 MEDIUM· v3 4.0 MEDIUM· v2 An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in the calendar application. |
7Arista CanonicalFedoraproject+4 more11Enterprise Linux EosFedora+8 moreNov 21, 2024 Jan 31, 2020 N/A· v4 3.5 LOW· v3 2.7 LOW· v2 The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop a...Show more |
1Novell 1Zenworks Configuration Management Nov 21, 2024 Jan 25, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Novell ZENworks Configuration Management before 11.2.4 allows obtaining sensitive trace information. |
1Novell 1Zenworks Configuration Management Nov 21, 2024 Jan 25, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Novell ZENworks Configuration Management before 11.2.4 allows XSS. |
5Canonical DebianEglibc+2 more5Debian Linux EglibcFedora+2 moreNov 21, 2024 Dec 31, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service. |
3Debian NovellQemu4Debian Linux Open Desktop ServerOpen Enterprise Server+1 moreNov 21, 2024 Dec 30, 2019 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the virtio device has zero/small sized config space, such as virtio-rng, a pr...Show more |
6Debian FedoraprojectGoogle+3 more9Backports ChromeDebian Linux+6 moreJun 17, 2026 Dec 10, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
4Debian MozillaNovell+1 more6Debian Linux FirefoxFirefox Esr+3 moreJun 17, 2026 Jul 23, 2019 N/A· v4 8.3 HIGH· v3 5.1 MEDIUM· v2 As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects...Show more |
4Debian MozillaNovell+1 more5Debian Linux FirefoxLeap+2 moreJun 17, 2026 Jul 23, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Fir...Show more |
4Canonical DebianFfmpeg+1 more4Debian Linux FfmpegSuse Package Hub For Suse Linux Enterprise+1 moreJun 17, 2026 Apr 19, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of service (NULL pointer dereference and out-of-array access) or possibly have...Show more |
The LDAP backend in Novell eDirectory before 9.0 SP4 when switched to EBA (Enhanced Background Authentication) kept open connections without EBA. |
In Novell eDirectory before 9.0.3.1 the LDAP interface was not strictly enforcing cipher restrictions allowing weaker ciphers to be used during SSL BIND operations. |
6Canonical DebianGoogle+3 more8Android Debian LinuxDnsmasq+5 moreMay 13, 2026 Oct 3, 2017 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS req...Show more |
5Canonical DebianNovell+2 more7Debian Linux DnsmasqEnterprise Linux Desktop+4 moreMay 13, 2026 Oct 3, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6 forwarded requests. |
6Canonical DebianFedoraproject+3 more8Debian Linux DnsmasqEnterprise Linux Desktop+5 moreMay 13, 2026 Oct 3, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xff...Show more |
2Novell Opensuse3Leap Suse Linux Enterprise DesktopSuse Linux Enterprise ServerMay 13, 2026 Sep 8, 2017 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 The mkdumprd script called "dracut" in the current working directory "." allows local users to trick the administrator into executing code as root. |
1Novell 1Zenworks Configuration Management May 13, 2026 Aug 9, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Stack-based buffer overflow in the logging functionality in the Preboot Policy service in Novell ZENworks Configuration Management (ZCM) allows remote attackers to execute arbitrary code via unspecified vectors. |